Of these 202.153.35.133 is the essential one to block traffic to, belonging to Excell Media Pvt Ltd in India. A file axybT95.exe is also dropped according to the report, which has a detection rate of 7/48.

I haven't seen a huge number of these, the format of the URLs looks something like this:
http://[redacted]/.-NEW_RECEIVED.FAX/fax.htmlhttp://[redacted]/NEW_FAX-MESSAGES/fax.letter.htmlhttp://[redacted]/_~NEW.FAX.MESSAGES/incoming.html